Troj/Delf-KO is a keylogging Trojan for the Windows platform.
When first run Troj/Delf-KO copies itself to:
<System>\destroy11.exe
<System>\destroyb11.exe
The following registry entry is created to run destroy11.exe on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
destroy11
destroy11.exe
The following registry entry is set, so that destroyb11.exe is run when files with extensions of TXT are opened/launched:
HKCR\txtfile\shell\open\command
(default)
destroyb11.exe %1
Troj/Delf-KO sends any logfiles to a pre-specified email address.